Vulnerability Description
Diasoft File Replication Pro 7.5.0 allows attackers to escalate privileges by replacing a legitimate file with a Trojan horse that will be executed as LocalSystem. This occurs because %ProgramFiles%\FileReplicationPro allows Everyone:(F) access.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Filereplicationpro | File Replication Pro | 7.5.0 |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/171879/File-Replication-Pro-7.5.0-Insecure-ExploitThird Party AdvisoryVDB Entry
- https://www.filereplicationpro.comProduct
- http://packetstormsecurity.com/files/171879/File-Replication-Pro-7.5.0-Insecure-ExploitThird Party AdvisoryVDB Entry
- https://www.filereplicationpro.comProduct
FAQ
What is CVE-2023-26918?
CVE-2023-26918 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Diasoft File Replication Pro 7.5.0 allows attackers to escalate privileges by replacing a legitimate file with a Trojan horse that will be executed as LocalSystem. This occurs because %ProgramFiles%\F...
How severe is CVE-2023-26918?
CVE-2023-26918 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2023-26918?
Check the references section above for vendor advisories and patch information. Affected products include: Filereplicationpro File Replication Pro.